Palo Alto Networks' Unit 42 reported that a Chinese-speaking threat actor (tracked via aliases knaithe and KnYuan) used DeepSeek through the open-source Hermes Agent framework to conduct autonomous cyber attacks. After a single initial Telegram instruction, the agent independently discovered internet-facing systems and selected public exploits with no further operator input. The actor launched exploitation attempts against more than 460 targets across seven exploit tracks spanning eight CVEs. While DeepSeek-led attacks against Langflow and n8n failed due to configuration requirements, manual operations succeeded in exfiltrating data from three organisations via CVE-2026-3055 (NetScaler memory-overread) and achieving command execution on 11 systems. This marks the third documented case in a week of autonomous AI agents being deployed for offensive cyber operations.
See: Cyber Digest โ 2026-08-01